---
sourceDocument: Australia Platform security
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/platform-security

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Configure Service Portal Widgets Allow List \[New in Security Center 2.0\]

# Configure Service Portal Widgets Allow List \[New in Security Center 2.0\] {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 Minute Lesedauer

Learn how to configure the glide.service_portal.widget.allow_list property securely
so that the access control lists (ACLs) for the tables do not expose sensitive
information.
The glide.service_portal.widget.allow_list property identifies
the widgets that can access any table within the instance. However, the access
control lists (ACLs) for these tables will continue to apply. If the ACLs are
incorrectly configured or absent, widgets on this list might enable access to these
tables, potentially exposing sensitive information. This property is effective only
if the widget uses SNCACLWidgetUtil and the
glide.service_portal.widget.enforce_public_check property
is enabled (set to true).

## More information {#sc_configure_service_portal_widgets_allow_list__section_qhx_1b1_xwb}

{#sc_configure_service_portal_widgets_allow_list__table_ajc_b43_3kb__entry__2}

| Attribute | Description |
|-|-|
| Configuration name | glide.service_portal.widget.allow_list |
| Configuration type | System Properties (/sys_properties_list.do) |
| Data type | array |
| Recommended value | Empty |
| Default value | Empty - in some customer's cases there might be some values. |
| Category | [Access control](https://servicenow-prod.fluidtopics.net/xAmazkRh5FKyeb7q4TQGWw "The access control category audits the process of protecting resources from unauthorized access through granting and denying requests based on a permission model. This includes ensuring an entity accessing a resource holds valid credentials to do so, creating and protecting a well-defined set of roles or permissions and ensuring role or permission controls are protected from replay and tampering.") |
| Security risk | * Severity score: 3.7 * CVSS score: Low * Security risk details: Not configuring this property to the recommended values could enable widgets to access any table within the instance. {#sc_configure_service_portal_widgets_allow_list__ul_g1g_3sf_xwb} |
| Dependencies and prerequisites | For the glide.service_portal.widget.allow_list setting to be applicable, the glide.service_portal.widget.enforce_public_check property must be set to true. |
| Functional impact | This property enables customers to access any table information if the widget is set to public and is included in the property's value. |
[ ]

{#sc_configure_service_portal_widgets_allow_list__table_ajc_b43_3kb}

